Privacy Policy
What we collect, why we collect it, who else processes it, how long we keep it, and how to get it back or have it deleted. Written to be read rather than to be survived.
Last updated 10 August 2026
1. Who is responsible
Brave People LLC, doing business as UX Signal, of 625 Bakers Bridge Ave, Ste 105 #146, Franklin, TN 37067 is the controller of the personal data described here. Contact us at hello@bravepeople.co.
2. What we collect
- Account data. Your email address, the name you choose to display, and a profile image if you upload one. Authentication is handled by Supabase; passwords are stored by them and are never visible to us.
- What you submit. The URLs you audit, the site type and audience you select, and any team or brand details you enter.
- What an audit produces. Screenshots of the page as rendered, extracted page text, the findings and scores derived from them, and the timing of the run.
- Billing data. Plan, status and renewal dates. Card details go directly to Stripe and are never stored on our systems.
- Technical data. Server logs including IP address, user agent and request times, kept for security and debugging.
We do not run advertising or analytics trackers, and we do not buy personal data from third parties.
3. A note on audited pages
When you audit a page, we capture and process what that page displays. If a page happens to show personal data — a team roster, a review with a name attached, a photograph — that content is captured too, and is sent to our analysis provider along with the rest of the page. Only audit pages you are entitled to audit, and avoid submitting pages you know to contain other people's personal information. Where we process such content we do so as a processor acting on your instructions.
4. Why we process it, and on what basis
- To provide the service you asked for — running audits, storing reports, operating your account. Basis: performance of a contract.
- To take payment and keep billing records. Basis: contract, and legal obligation for tax records.
- To keep the service secure, prevent abuse, and debug failures. Basis: our legitimate interest in a service that works and is not misused.
- To contact you about the service, including changes that affect you. Basis: contract, or legitimate interest.
- To send marketing, only where you have opted in. Basis: consent, withdrawable at any time.
5. Who else processes it
We use a small number of sub-processors. Each is bound to process data only on our instructions.
- Supabase — authentication, database and file storage. Supabase also sends the sign-in emails, since authentication is by emailed link.
- Anthropic — analysis of captured page content and screenshots to produce findings. Content submitted through the API is not used to train their models.
- Railway — application hosting, server logs, and the object storage holding audit screenshots.
- Stripe — payment processing. Stripe is a controller in its own right for payment data.
There is no separate analytics, advertising, error-monitoring or marketing-email provider in the stack. If we add one, it will be listed here before it starts receiving data.
We otherwise disclose personal data only where required by law, to enforce our terms, or as part of a merger or acquisition — in which case we will tell you before your data becomes subject to a different policy.
6. International transfers
Our providers operate in the United States — the database and authentication in US East, hosting and screenshot storage in US West — so your data may be processed outside your country. Where data leaves the UK or EEA we rely on the UK IDTA or the EU Standard Contractual Clauses, together with the additional safeguards those require.
7. How long we keep it
- Audits, including their screenshots, are kept until you delete them or close your account. Deleting an audit removes the record and its capture files; it cannot be undone.
- Account data is kept while your account is open and deleted within 30 days of closure, save where we must keep records longer.
- Billing records are kept for as long as tax law requires, typically six to seven years.
- Server logs are kept for a short operational window and then discarded.
8. Your rights
Depending on where you live you may have the right to access a copy of your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent. If you are in the UK or EEA you may complain to your supervisory authority; if you are in California you have rights of access, deletion and correction, and we do not sell or share personal information as those terms are defined there.
Much of this is self-service: you can edit your profile, delete individual audits or a whole domain's history, and revoke shared links from inside the app. For anything else, write to hello@bravepeople.co and we will respond within one month.
9. Security
Data is encrypted in transit and at rest by our infrastructure providers, access is limited to those who need it, and shared report links use unguessable tokens and are excluded from search indexing. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authority as the law requires.
10. Children
The service is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child has given us data, contact us and we will delete it.
11. Changes
We will post any update here and change the date above. Where a change materially affects how we use your data, we will tell you directly.